GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,549
Maven
5,000+
npm
5,000+
NuGet
917
pip
4,798
Pub
13
RubyGems
1,038
Rust
1,237
Swift
53
Unreviewed advisories
All unreviewed
5,000+
4,701 advisories
Filter by severity
elFinder: Command injection in resize background color parameter when using ImageMagick CLI
High
GHSA-8q4h-8crm-5cvc
was published
for
studio-42/elfinder
(Composer)
Apr 17, 2026
Incomplete fix for CVE-2026-34935: Command Injection in MervinPraison/PraisonAI
Critical
GHSA-9qhq-v63v-fv3j
was published
for
praisonai
(pip)
Apr 17, 2026
OpenClaw: Shell-wrapper detection missed env-argv assignment injection forms
Moderate
GHSA-j6c7-3h5x-99g9
was published
for
openclaw
(npm)
Apr 17, 2026
radare2 prior to commit bc5a890 contains a command injection vulnerability in the afsv/afsvj...
High
Unreviewed
CVE-2026-40527
was published
Apr 17, 2026
Dolibarr: OS Command Injection (RCE) via MAIN_ODT_AS_PDF configuration
Critical
CVE-2026-23500
was published
for
dolibarr/dolibarr
(Composer)
Apr 17, 2026
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0...
Moderate
Unreviewed
CVE-2026-35074
was published
Apr 17, 2026
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0...
Moderate
Unreviewed
CVE-2026-35072
was published
Apr 17, 2026
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0...
Moderate
Unreviewed
CVE-2026-35073
was published
Apr 17, 2026
An OS command injection vulnerability exists in CubeCart prior to 6.6.0, which may allow a user...
High
Unreviewed
CVE-2026-21719
was published
Apr 17, 2026
sagredo qmail before 2026.04.07 allows tls_quit remote code execution because of popen in...
High
Unreviewed
CVE-2026-41113
was published
Apr 17, 2026
Paperclip: OS Command Injection via Execution Workspace cleanupCommand
Critical
GHSA-vr7g-88fq-vhq3
was published
for
@paperclipai/server
(npm)
Apr 16, 2026
Paperclip: Privilege Escalation via Agent-Controlled workspaceStrategy.provisionCommand Leading to OS Command Execution
High
GHSA-265w-rf2w-cjh4
was published
for
@paperclipai/server
(npm)
Apr 16, 2026
WWBN AVideo: RCE cause by clonesite plugin
High
GHSA-xr6f-h4x7-r6qp
was published
for
wwbn/avideo
(Composer)
Apr 16, 2026
Flowise: Authenticated RCE Via MCP Adapters
Critical
CVE-2026-40933
was published
for
flowise
(npm)
Apr 16, 2026
radare2 before 9236f44, when configured on UNIX without SSL, allows command injection via a PDB...
High
Unreviewed
CVE-2026-41015
was published
Apr 16, 2026
The
iSherlock developed by HGiga has an OS Command Injection vulnerability, allowing...
Critical
Unreviewed
CVE-2026-6349
was published
Apr 16, 2026
radare2 prior to version 6.1.4 contains a command injection vulnerability in the PDB parser's...
High
Unreviewed
CVE-2026-40499
was published
Apr 16, 2026
WWBN AVideo has an incomplete fix for CVE-2026-33502: Command Injection
High
GHSA-pq8p-wc4f-vg7j
was published
for
wwbn/avideo
(Composer)
Apr 14, 2026
PowerShell Command Injection in Podman HyperV Machine
Moderate
CVE-2026-33414
was published
for
github.com/containers/podman/v4
(Go)
Apr 14, 2026
Composer has a command injection via malicious perforce repository
High
CVE-2026-40176
was published
for
composer/composer
(Composer)
Apr 14, 2026
Composer has a command injection via malicious perforce reference
High
CVE-2026-40261
was published
for
composer/composer
(Composer)
Apr 14, 2026
A improper neutralization of special elements used in an os command ('os command injection')...
Critical
Unreviewed
CVE-2026-39808
was published
Apr 14, 2026
SSH/SCP option injection allowing local RCE in @aiondadotcom/mcp-ssh
High
GHSA-p4h8-56qp-hpgv
was published
for
@aiondadotcom/mcp-ssh
(npm)
Apr 14, 2026
Improper Neutralization of Special Elements used in an OS Command vulnerability allows OS Command...
High
Unreviewed
CVE-2026-30806
was published
Apr 13, 2026
Improper Neutralization of Special Elements used in an OS Command vulnerability allows OS Command...
High
Unreviewed
CVE-2026-34188
was published
Apr 13, 2026
ProTip!
Advisories are also available from the
GraphQL API